Skip to content
COOEY

EXPOSURES › CVE-2025-59689

CVE-2025-59689

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-09-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-59689 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Libraesva Email Security Gateway suffered command injection through e-mail attachments, actively exploited in the wild

Libraesva Email Security Gateway (ESG) allowed attackers to execute arbitrary commands through maliciously crafted email attachments, a flaw actively exploited by cyber actors. This exposed sensitive data and systems to potential compromise.

Shame score — Active exploitation of a critical vulnerability in a widely used product by the DIB, leading to potential unauthorized command execution and data breach risks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.